ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1074.001×

95 examples

TechniqueUsed byProcedure example
T1074.001
Local Data Staging
MalwareExaramel for Windows

Exaramel for Windows specifies a path to store files scheduled for exfiltration.

T1074.001
Local Data Staging
MalwareNOKKI

NOKKI can collect data from the victim and stage it in LOCALAPPDATA%\MicroSoft Updatea\uplog.tmp.

T1074.001
Local Data Staging
MalwareKOPILUWAK

KOPILUWAK has piped the results from executed C2 commands to `%TEMP%\result2.dat` on the local machine.

T1074.001
Local Data Staging
MalwareVersaMem

VersaMem staged captured credentials locally at `/tmp/.temp.data`.

T1074.001
Local Data Staging
MalwarePAKLOG

PAKLOG has stored the captured data in a file located `C:\\Users\\Public\\Libraries\\record.txt`.

T1074.001
Local Data Staging
MalwareUrsnif

Ursnif has used tmp files to stage gathered information.

T1074.001
Local Data Staging
MalwareFrameworkPOS

FrameworkPOS can identifiy payment card track data on the victim and copy it to a local file in a subdirectory of C:\Windows\.

T1074.001
Local Data Staging
MalwareInvisibleFerret

InvisibleFerret has staged data in consolidated folders prior to exfiltration.

T1074.001
Local Data Staging
MalwareRainyDay

RainyDay can use a file exfiltration tool to copy files to C:\ProgramData\Adobe\temp prior to exfiltration.

T1074.001
Local Data Staging
MalwareAppleSeed

AppleSeed can stage files in a central location prior to exfiltration.

T1074.001
Local Data Staging
MalwareNETWIRE

NETWIRE has the ability to write collected data to a file created in the ./LOGS directory.

T1074.001
Local Data Staging
MalwareMirrorStealer

MirrorStealer has stored stolen credentials on the local machine in `%TEMP%\31558.txt`.

T1074.001
Local Data Staging
MalwareTurian

Turian can store copied files in a specific directory prior to exfiltration.

T1074.001
Local Data Staging
MalwareMachete

Machete stores files and logs in a folder on the local drive.

T1074.001
Local Data Staging
MalwarePowerLess

PowerLess can stage stolen browser data in `C:\\Windows\\Temp\\cup.tmp` and keylogger data in `C:\\Windows\\Temp\\Report.06E17A5A-7325-4325-8E5D-E172EBA7FC5BK`.

T1074.001
Local Data Staging
MalwarePrikormka

Prikormka creates a directory, %USERPROFILE%\AppData\Local\SKC\, which is used to store collected log files.

T1074.001
Local Data Staging
MalwareMafalda

Mafalda can place retrieved files into a destination directory.

T1074.001
Local Data Staging
MalwareAuTo Stealer

AuTo Stealer can store collected data from an infected host to a file named `Hostname_UserName.txt` prior to exfiltration.

T1074.001
Local Data Staging
MalwareSombRAT

SombRAT can store harvested data in a custom database under the %TEMP% directory.

T1074.001
Local Data Staging
MalwareFLASHFLOOD

FLASHFLOOD stages data it copies from the local system or removable drives in the "%WINDIR%\$NtUninstallKB885884$\" directory.

T1074.001
Local Data Staging
MalwareLoFiSe

LoFiSe can save files to be evaluated for further exfiltration in the `C:\Programdata\Microsoft\` and `C:\windows\temp\` folders.

T1074.001
Local Data Staging
MalwareCuckoo Stealer

Cuckoo Stealer has staged collected application data from Safari, Notes, and Keychain to `/var/folder`.

T1074.001
Local Data Staging
MalwareInvisiMole

InvisiMole determines a working directory where it stores all the gathered data about the compromised machine.

T1074.001
Local Data Staging
MalwareMarkiRAT

MarkiRAT can store collected data locally in a created .nfo file.

T1074.001
Local Data Staging
MalwareKazuar

Kazuar stages command output and collected data in files before exfiltration.

T1074.001
Local Data Staging
MalwareNavRAT

NavRAT writes multiple outputs to a TMP file using the >> method.

T1074.001
Local Data Staging
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP can store captured screenshots to disk including to a covert store named `APPX.%x%x%x%x%x.tmp` where `%x` is a random value.

T1074.001
Local Data Staging
MalwareChrommme

Chrommme can store captured system information locally prior to exfiltration.

T1074.001
Local Data Staging
MalwareObliqueRAT

ObliqueRAT can copy specific files, webcam captures, and screenshots to local directories.

T1074.001
Local Data Staging
MalwareSocGholish

SocGholish can send output from `whoami` to a local temp file using the naming convention `rad<5-hex-chars>.tmp`.

T1074.001
Local Data Staging
MalwarePUNCHBUGGY

PUNCHBUGGY has saved information to a random temp file before exfil.

T1074.001
Local Data Staging
MalwarePteranodon

Pteranodon creates various subdirectories under %Temp%\reports\% and copies files to those subdirectories. It also creates a folder at C:\Users\<Username>\AppData\Roaming\Microsoft\store to store screenshot JPEG files.

T1074.001
Local Data Staging
MalwareBeaverTail

BeaverTail has staged collected data to the system’s temporary directory.

T1074.001
Local Data Staging
MalwareDarkWatchman

DarkWatchman can stage local data in the Windows Registry.

T1074.001
Local Data Staging
MalwareDyre

Dyre has the ability to create files in a TEMP folder to act as a database to store information.

T1074.001
Local Data Staging
MalwarePACEMAKER

PACEMAKER has written extracted data to `tmp/dsserver-check.statementcounters`.

T1074.001
Local Data Staging
MalwarePlugX

PlugX has collected and staged the victim’s computer files for exfiltration.

T1074.001
Local Data Staging
MalwareLumma Stealer

Lumma Stealer has configured a custom user data directory such as a folder within `%USERPROFILE%\AppData\Roaming` for staging data.

T1074.001
Local Data Staging
MalwareDustySky

DustySky created folders in temp directories to host collected files before exfiltration.

T1074.001
Local Data Staging
MalwareRover

Rover copies files from removable drives to C:\system.

T1074.001
Local Data Staging
MalwareLightNeuron

LightNeuron can store email data in files and directories specified in its configuration, such as C:\Windows\ServiceProfiles\NetworkService\appdata\Local\Temp\.

T1074.001
Local Data Staging
MalwareElise

Elise creates a file in AppData\Local\Microsoft\Windows\Explorer and stores all harvested data in that file.

T1074.001
Local Data Staging
MalwareLODEINFO

LODEINFO has collected stolen web cookies locally in the `%TEMP%` folder.

T1074.001
Local Data Staging
MalwareSagerunex

Sagerunex gathers host information and stages it locally as a RAR file prior to exfiltration. Sagerunex stores logged data in an encrypted file located at `%TEMP%/TS_FB56.tmp` during execution.

T1074.001
Local Data Staging
MalwareLP-Notes

LP-Notes has stored collected credentials in ` C:\Users\Public\Downloads\lp-notes.txt`.

T1074.001
Local Data Staging
MalwareGlassWorm

GlassWorm has staged collected data in a working directory within a temp folder to include `/tmp/ijewf`.

T1074.001
Local Data Staging
MalwareTrojan.Karagany

Trojan.Karagany can create directories to store plugin output and stage data for exfiltration.

T1074.001
Local Data Staging
MalwareSPACESHIP

SPACESHIP identifies files with certain extensions and copies them to a directory in the user's profile.

T1074.001
Local Data Staging
MalwareKGH_SPY

KGH_SPY can save collected system information to a file named "info" before exfiltration.

T1074.001
Local Data Staging
MalwareCatchamas

Catchamas stores the gathered data from the machine in .db files and .bmp files under four separate locations.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.